How do you open security posture monitoring?

Open the view from the application menu: Menu -> Monitoring -> Security. It is used to review security posture snapshots collected from employees' computers. In the table and panel you can see Security Score, the number of Problems, BitLocker, Windows Update, Defender, Firewall, Secure Boot and TPM statuses, as well as Enabled, Disabled and Unknown controls, Warnings and Critical findings.

Open this view when you want to quickly check which workstations have a lower protection level, whether an important control has been disabled, whether warnings are increasing and whether the issue affects one computer or a wider device group. Security posture monitoring gives administrative context: it describes the condition of system protection, not the content of user work.

The page combines the Analytics Panel with a records table and details. The panel presents metrics, control rankings, status distributions, trends, comparisons, anomalies, hourly presence and data quality. A table row is a daily security snapshot saved for a specific computer. Selecting the record opens the control picture for that day, workstation and employee, divided by status, severity, area and detection time.


Daily table in computer security monitoring

The daily table lets you immediately separate protected computers from those that need review. The score itself matters, but so does the control that lowers it and whether the status changed compared with the device's usual behavior.

The first table view includes, among others:

  • Security Score - the percentage score calculated from controls stored in the snapshot.
  • Problems - the number of items that need attention.
  • BitLocker - information about disk encryption or its state.
  • Windows Update - the update service status and start type.
  • Last Warning - the last problem description saved in the record.

After expanding columns, you can review Security Status, Defender, Firewall, Secure Boot, TPM, enabled, disabled and unknown controls, warnings, critical findings, Last Control, Last Status and Windows Update Start Type. Search covers Active Hours, Security Status, Last Status, Details, Windows Update Status, Windows Update Start Type and the record details content.


Analytics panel in protection health monitoring

The analytics panel collects security snapshots from the selected date range and shows the general condition of computers. This view uses Sum mode, so problem, warning and control counts should be read as the combined picture of the analyzed period.

The key panel metrics are Security Score, Problems, Disabled, Warnings, Critical, Protected Computers, Computers, Employees and Protected Computers Percent. A high score with a small number of problems usually means stable protection, while growth in disabled controls requires checking whether critical protections are involved.

When interpreting the panel, do not stop at one percentage. A computer can have an acceptable score while still having an important control disabled. That is why the security score should be compared with the problem list, critical status and control details.


Control rankings in security monitoring

Rankings help determine which security controls appear most often in the data and where problems concentrate. Instead of starting from a single computer, you can first see whether the same control, the same status or the same workstation group repeats.

The ranking panel includes:

  • Security Controls - the list of controls most often present in details.
  • Control Statuses - the distribution of states such as enabled, disabled or unknown.
  • Top Computers - computers with the largest number of security items.
  • Top Employees - users linked to the largest number of snapshots or controls.

If a high-importance control appears at the top of the ranking, go to record details and check its status and severity. If Unknown dominates, the problem may come from missing readout of that information rather than from protection actually being disabled.


Security score trends in computer monitoring

Trends show how security posture changed over time. You can switch charts for Security Score, Problems, disabled controls, Warnings, critical findings and Protected Computers.

When analyzing trends, check:

  • whether the security score drop concerns one day or lasts longer,
  • whether growth in problems comes together with more warnings or critical findings,
  • whether the number of disabled controls rises after an update, policy change or rollout,
  • whether the number of protected computers decreases despite a similar number of monitored workstations,
  • whether the issue appears at the same time in Defender, Firewall, BitLocker or Windows Update.

The Hourly Security Posture Presence chart shows the percentage of monitored days in which a security snapshot was recorded during a given local hour. It is not the number of problems or the duration of a lowered protection state; a marked hour only says that the snapshot was captured then.


Security posture comparisons in work monitoring

Comparisons place the current range next to a reference period and show whether protection health improved, worsened or changed structure. This view is especially useful after policy changes, system updates, new agent rollout or larger administrative work.

In the comparisons tab, look at:

  • the change in Security Score, especially when the number of problems grows at the same time.
  • the difference in Disabled, because it shows the number of controls that stopped being active.
  • growth in Warnings, which can appear before a critical state.
  • the change in Critical, because it indicates the most serious findings.
  • Protected Computers Percent, to assess whether the issue concerns protection coverage rather than only individual entries.

If the comparison shows deterioration, start with the control ranking and then narrow the analysis to computers and details. This order helps you establish faster whether the cause is one control, a group of devices or a general configuration change.


Anomalies in security posture monitoring

Anomalies point to situations where security posture needs additional attention. The mechanism analyzes both individual records and change against the comparison period, so the panel may show warnings about a specific computer's state and about problem growth across the whole range.

The view may show, among others:

  • Critical security posture detected - when a computer has at least one critical finding.
  • Important security control is disabled - when a control treated as important is not working on a monitored computer.
  • New disabled security control detected - when a control is disabled now but was not disabled in the comparison period.
  • Security posture warnings increased - when warnings are significantly higher than in the baseline range.

In anomaly evidence, check Critical Count, Security Status, Last Warning, control name, Status, Area, Computer, Current Warnings, Baseline Warnings and Warning Increase. An anomaly does not replace an administrator audit, but it clearly points to the workstation or control that should be reviewed first.


Record details in security control monitoring

After you click a record, the application shows security controls collected for one day and one computer. Details are aggregated by control, so one row can describe the state of a specific protection item, its status, severity and detection time.

The details table includes: Security Control, Status, Severity, Security Area, Item Key, First Seen, Last Seen and Active Hours. Source data also contains category, source, source type, name and details, which help determine where the control information came from.

First sort by severity or status to see the most serious items. Then check the security area and active hours. Details cannot be narrowed with an hourly filter because the hour mask stores snapshot presence, but does not assign individual security states to specific hours.


Data quality in security posture monitoring

The data quality section helps assess whether security posture details are complete and match the daily summary. This is important because the view combines aggregate metrics with a control list, and some information may appear only after record aggregation finishes.

The quality panel can signal a missing control list, invalid detail data format, timestamps outside the day range, a mismatch between the summary and items, unfinished aggregation of the current day or an older closed record without a complete detail set.

For today's records, treat a quality alert as a sign that the snapshot may still be closing and being prepared. For older records, check agent operation, availability of system data, the send queue and whether the security snapshot contains the items needed for comparison with the summary.


Audit scope in security monitoring

The Security view uses a security posture snapshot collected by the agent. In profile settings files there are options Security Posture Audit and Security Posture Audit Interval (minutes), but they are marked as read-only. This means that in this panel version we do not describe them as editable user settings.

In practice, remember three things:

  • the snapshot shows the state at read time, not a continuous log of every security change.
  • missing data for a control can mean Unknown status, a readout problem or lack of support for that information on the computer.
  • the security score should be read together with details, because one high-severity control can matter more than the number of problems alone.

That is why security posture monitoring is best treated as a quick control screen for administrators. First it points to computers and controls that need attention, and only record details help decide whether intervention, another data readout or security policy verification is needed.